Description
In the Linux kernel, the following vulnerability has been resolved:

iio: light: ltrf216a: fix runtime PM reference leak in error path

ltrf216a_get_lux() acquires a runtime PM reference by calling
ltrf216a_set_power_state(data, true). However, if
ltrf216a_read_data() fails, the function returns immediately without
dropping the reference.

This leaves the runtime PM usage count unbalanced, preventing the device
from autosuspending after a failed read.

Fix this by releasing the runtime PM reference before returning from the
error path.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The driver for the ltrf216a light sensor in the Linux kernel leaks a runtime power management reference when read operations fail. The leaked reference prevents the kernel from decrementing the PM usage count, blocking the device from autosuspending. This results in the sensor staying powered unnecessarily, potentially draining battery or wasting system power and effectively denying the intended power‑management service.

Affected Systems

The vulnerability exists in the Linux kernel, affecting any build that includes the ltrf216a light sensor driver. No specific kernel version boundaries are provided, so all kernel versions that ship the driver until the patch are potentially impacted.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a low probability of real‑world exploitation, and the issue is not listed in the CISA KEV catalog. The CVSS score is not supplied. Attackers would need to induce a read failure in the ltrf216a driver—likely requiring local or privileged access—to trigger the reference leak. Even if exploited, the impact is limited to loss of autosuspend functionality, passing the risk level to device‑level denial of service rather than system‑wide compromise.

Generated by OpenCVE AI on September 18, 2026 at 07:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the fix for the ltrf216a driver’s runtime power‑management reference leak.
  • Reboot the system or reload the affected module so the reference counting starts anew.
  • If an immediate kernel update is not possible, consider disabling the ltrf216a driver until the patch can be applied to prevent the reference leak.

Generated by OpenCVE AI on September 18, 2026 at 07:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-674

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: light: ltrf216a: fix runtime PM reference leak in error path ltrf216a_get_lux() acquires a runtime PM reference by calling ltrf216a_set_power_state(data, true). However, if ltrf216a_read_data() fails, the function returns immediately without dropping the reference. This leaves the runtime PM usage count unbalanced, preventing the device from autosuspending after a failed read. Fix this by releasing the runtime PM reference before returning from the error path.
Title iio: light: ltrf216a: fix runtime PM reference leak in error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:24.240Z

Reserved: 2026-09-11T19:38:34.776Z

Link: CVE-2026-89934

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:02.800

Modified: 2026-09-16T11:17:02.800

Link: CVE-2026-89934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-674

    Uncontrolled Recursion